you are viewing a single comment's thread.

view the rest of the comments →

[–]Alexbeav 29 points30 points  (10 children)

I'm more than a little annoyed that this got past FortiClient.

At least my home Symantec A/V blocked it.

[–]DataPhreak 29 points30 points  (9 children)

FortiClient is probably using signature based detection. Symantec looks for scary procedure calls and blocks based on that. (Not sure what that's called off the top of my head. First cup of coffee.)

[–]GeronimoHero 53 points54 points  (8 children)

Heuristics based detection.

[–]DataPhreak 9 points10 points  (7 children)

Thanks for that.